CVE-2026-3902Disclosure(djangoproject / django)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch djangoproject django systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) to a single version with underscores. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • django

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-07); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
django

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-07: 3Mentions · 2026-04-10: 1Mentions · 2026-04-19: 1Patch / Workaround · 2026-04-07: 1Technical Details · 2026-04-07: 3Technical Details · 2026-04-19: 104-0704-1004-19
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-073
Disclosure2Patch1
2026-04-101
General1
2026-04-191
Disclosure1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Patch

    5 CVEs fixed in Django https://www.openwall.com/lists/oss-security/2026/04/07/10 CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable + next tweet

    Post summary

    The tweet announces that five Django CVEs have been fixed, providing brief technical details for several of them and confirming patch availability.

    10050638
    4.6K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Django ❗ CVE-2026-3902 ❗ CVE-2026-33034 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-django-2/ https://t.co/Y4RdtjMbku

    Post summary

    A brief tweet that lists two Django product CVEs and directs readers to a CERT page for further information, but it lacks additional technical details, patches, or exploitation evidence.

    00010101
    6.6K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A high-severity Django vulnerability, CVE-2026-3902, allows ASGI header spoofing via underscore/hyphen conflation. Review Django and ASGI server configurations. #Django #ASGI #Security https://www.pulsepatch.io/posts/cve-2026-3902-django-asgi-header-spoofing

    Post summary

    The post announces the high‑severity Django CVE‑2026‑3902 vulnerability that allows ASGI header spoofing through underscore/hyphen conflation and urges readers to review server configurations.

    0000060
    12 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3902 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguou… https://www.cve.org/CVERecord?id=CVE-2026-3902 ----- Traducción: CVE-2026-3902 Se … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-3902, outlining affected software versions and the capability to spoof headers via ASGIRequest, without indicating an exploit, active exploitation, or mitigation.

    0000030
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3902 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguou… https://www.cve.org/CVERecord?id=CVE-2026-3902

    Post summary

    The text reports CVE‑2026‑3902 as a header‑spoofing issue in specific software versions, providing a brief technical description but offering no PoC, exploit code, or patch information.

    00000179
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdjangoprojectdjango---

Explore more